Last May saw the biggest change to the data protection landscape in decades with the introduction of the GDPR and the Data Protection Act 2018. One year on and the ICO has released an update to share its thoughts and learnings from the past 12 months. It acknowledges that although many organisations have spent a considerable amount of time and resource in preparing for the GDPR, compliance is an ongoing battle and the focus for the next year will be around accountability, and ensuring organisations take responsibility for how and why they process personal data.

Breach handling and managing requests and complaints from data subjects are clearly some of the biggest challenges organisations face. In the past year, 14,000 data breaches were reported to the ICO and 41,000 complaints were made by the public (38% of which related to the handling of subject access requests). The health sector accounted for 16% of personal data breaches reported to the ICO and 7% of complaints, and local government accounted for 8% of personal data breaches reported and 9% of complaints.

Although no fines have been levied by the ICO under the new legislation, it is only a matter of time, and with Brexit looming and further updates and guidance from the ICO due in the next few months, the data protection landscape is likely to continue to shift and develop.

For advice or assistance around data protection, Bevan Brittan’s specialist Information Law team would be happy to help.

Our use of cookies

We use necessary cookies to make our site work. We'd also like to set optional analytics cookies to help us improve it. We won't set optional cookies unless you enable them. Using this tool will set a cookie on your device to remember your preferences. For more detailed information about the cookies we use, see our Cookies page.

Necessary cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Analytics cookies

We'd like to set Google Analytics cookies to help us to improve our website by collection and reporting information on how you use it. The cookies collect information in a way that does not directly identify anyone.
For more information on how these cookies work, please see our Cookies page.